VYPR
researchPublished Sep 21, 2026· 1 source

Meta Muse AI App Vulnerability Allows Local Malware to Hijack Dictation Traffic

A flaw in Meta's Muse AI app enables local malware to redirect dictation traffic, potentially exposing sensitive user data and authentication credentials.

Security researcher Patrick Wardle has uncovered a local privilege escalation vulnerability within Meta's Muse AI macOS application, dubbed 'not-a-mused'. This flaw, requiring only local code execution, allows an unprivileged process to modify an undocumented setting, endo_voyager_dictation_endpoint. By altering this setting, an attacker can redirect the app's dictation traffic to an endpoint they control.

This redirection poses significant risks, potentially exposing not only dictated audio and user prompts sent to the AI model but also authentication material. Wardle demonstrated that this could lead to prompt injection attacks and the theft of sensitive credentials. While the vulnerability is not accessible to remote attackers, it significantly amplifies the capabilities of existing local malware, effectively acting as a privilege escalation mechanism.

Wardle highlighted concerns about the broad access requested by many AI applications, even those that claim to prioritize user privacy. He likened the situation to an apartment building where a new neighbor shouldn't have access to all units, emphasizing that AI apps, by design, often require extensive permissions to be useful. This extensive access, he argues, can undermine the security controls meticulously built into operating systems like macOS.

Meta's marketing for Muse emphasized its security features, including the use of a "Muse Secure VM" and user control over data access. However, Wardle suggests that the company's pursuit of user data may have led to a larger attack surface. He pointed out that Meta could have utilized Apple's on-device dictation API, which would have prevented this vulnerability, implying a deliberate choice to access and potentially monetize user data.

The researcher questioned the internal security practices of AI companies, asking if they are running their own bug-finding AI models against their applications. He noted that while endpoint detection and response (EDR) tools have improved on macOS due to code signing and notarization, the broad permissions granted to AI agents make it difficult for EDRs to distinguish between legitimate user commands, agent actions, and malicious activity.

Wardle's findings underscore a growing tension between the utility of AI applications and the security implications of their extensive system access. As AI tools become more integrated into daily workflows, the responsibility of AI developers to ensure the security and privacy of their applications becomes paramount. The potential for these powerful tools to become single points of failure for operating system security is a critical concern for the cybersecurity community.

Meta had not immediately responded to a request for comment at the time of reporting. The vulnerability highlights the need for greater scrutiny of AI application permissions and a more proactive approach to security by AI developers, especially concerning the handling of sensitive user data and authentication mechanisms.

Synthesized by Vypr AI
Meta Muse AI App Vulnerability Allows Local Malware to Hijack Dictation Traffic · VYPR